logo

Expel Quarterly Threat Report: Cybersecurity data, trends, and recs from Q1 2022

ID: a4ecb0bd-f26d-572d-ad43-cc2da42ebb4c

STIX ID: report--a4ecb0bd-f26d-572d-ad43-cc2da42ebb4c

Feed Name: Expel Blog

Threat Score
70/100

Date Published: 2022-05-20

Date Updated: 2026-04-27

Author: Jonathan Hencinski

...
...

Expel’s Q1 2022 Quarterly Threat Report finds identity-based attacks comprised 65% of incidents (with BEC/BAC dominating), reports BEC in O365 as a major vector (57% of incidents), notes pre-ransomware activity and commodity malware deployment (macro-enabled Word and zipped JavaScript files common), documents MFA bypass techniques (malicious OAuth apps and push-fatigue attacks), and highlights operational outcomes including a 25-minute median alert-to-recommendation time for critical incidents.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.